Probably the most noticeable part of Active Directory administration is managing objects and resources within the Users and Computers snap-in.
Users and Computers mmc snap-in enables
you to create and manage objects like Users, Groups, Contacts, Computers and Organizational units (OUs). User is an object that represents a real person with their rights to access specific resources, and with attributes like personal data. More users can be grouped in a group which alows easier administration of larger number of users by managing only one group.
Althought users, groups and other objects are pretty self explanatory, organizational units or (OUs) can be thought of as a folders on a file system. By putting a user or resource in an OU, sysadmin can control who has administrative authority over that user or resource - in other words, for specific resources, Administrator can delegate portions of administrative authority to subadministrators.
A user can be a member of many groups but can only reside in one OU - just as a file can reside only in one folder.
Users and Computers snap-in can be started by going to Start > Programs > Administrative Tools > Active Directory Users and Computers, or simply by entering "dsa.msc" at the run prompt:
From Users and Computers snap-in we can creat and manage objects like Users, Groups, Contacts, Computers and organizational units (OUs):
If email Exchange server is installed in domain, the setup wizard automatically extends the functionality of Active Directory Users and Computers snap-in to include Exchange-specific tasks. So nice thing is that all can be administrated from one place:
From Users and Computers snap-in, creating a new domain user can be done by right clicking on default users folder:
Once from the context menu New > users is selected, users data such as username and email address can be entered (If exchange server is properly implemented and configured, there's no need for creating separate email account since it will be created automatically if entered):
From the user's properties, on the Member of tab is possible to add the user in a group. Be careful while promoting a user in a Domain administrator - this user has an absolute power in a domain:
Complete creation of new user by entering users password:
(Also, as a good security method and practice, it's a wise thing to set up expiration password policy for a whole domain, so that users must change their password every 2-3 months or so.)
Comments
Post a Comment